CVE-2026-57445
8.71Hive · gardens-v2
A logic error in the StreamingEscrow dispute resolution path of the 1Hive gardens-v2 governance framework allows for the unauthorized drainage of escrow balances to proposal beneficiaries.
Executive summary
A high-severity logic flaw in the 1Hive gardens-v2 governance framework allows unauthenticated attackers to drain entire escrow balances, posing a critical risk to community treasury funds.
Vulnerability
The vulnerability exists within the StreamingEscrow component where the approve-side dispute resolution path fails to correctly account for escrow reserves. This logic flaw permits an unauthenticated actor to trigger a transaction that drains the total available escrow balance instead of the expected amount.
Business impact
The exploitation of this vulnerability results in direct financial loss for the affected community governance pools. Given the CVSS score of 8.7, this is considered a high-severity issue that could lead to the complete depletion of project funds, severe reputational damage, and the loss of stakeholder trust in the decentralized governance mechanism.
Remediation
Immediate Action: As no official patch is currently available, administrators should immediately pause or restrict interactions with the affected StreamingEscrow contracts to prevent further exploitation.
Proactive Monitoring: Monitor on-chain activity for any anomalous withdrawal patterns or large-scale payouts from the StreamingEscrow pools that deviate from standard governance proposal outcomes.
Compensating Controls: Implement multisig requirements for sensitive administrative actions and consider deploying circuit breakers to pause contract functions if unexpected outflows are detected.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the significant financial risk posed by this vulnerability, stakeholders must treat this as an urgent matter. Governance participants should prioritize the development and audit of a corrective patch while maintaining defensive measures to lock down affected pools. Continued vigilance and proactive monitoring of treasury balances are essential until the vendor provides a secure update.